Apache Neethi: Policy Normalization Unbounded Resource Allocation DoS
Published May 1, 2026
7.5
HIGHCVSS 3.1
EPSS 0.74%
Description
Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documents can trigger an exponential Cartesian cross-product expansion during the normalization process, causing unbounded memory allocation that exhausts the JVM heap. This occurs when the normalization process generates an excessive number of policy alternatives without bounds, leading to runtime memory exhaustion.
Users should upgrade to 3.2.2 which limits the maximum number of normalized policy alternatives.
Affected products
-
- Version 0StatusaffectedConstraints<3.2.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Neethi | unaffected |
|
No data.
Red Hat Build of Apache Camel 4.14 for Quarkus 3.27
neethi
Fixed · RHSA-2026:19835
Red Hat Fuse 7
neethi
Fix deferred
Red Hat JBoss Enterprise Application Platform 7
neethi
Fix deferred
Red Hat JBoss Enterprise Application Platform 8
neethi
Fix deferred
Red Hat JBoss Enterprise Application Platform Expansion Pack
neethi
Fix deferred
Red Hat Process Automation 7
neethi
Fix deferred
Red Hat Single Sign-On 7
neethi
Fix deferred
Red Hat build of Apache Camel 4 for Quarkus 3
neethi
Affected
Red Hat build of Apache Camel for Spring Boot 4
neethi
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Build of Apache Camel 4.14 for Quarkus 3.27 | neethi | Fixed | RHSA-2026:19835 |
| Red Hat Fuse 7 | neethi | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | neethi | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | neethi | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | neethi | Fix deferred | n/a |
| Red Hat Process Automation 7 | neethi | Fix deferred | n/a |
| Red Hat Single Sign-On 7 | neethi | Fix deferred | n/a |
| Red Hat build of Apache Camel 4 for Quarkus 3 | neethi | Affected | n/a |
| Red Hat build of Apache Camel for Spring Boot 4 | neethi | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw is rated Moderate because Apache Neethi, as used in Red Hat products, is susceptible to a denial of service. Remote attackers can provide malicious WS-Policy documents, leading to an algorithmic complexity issue during policy normalization. This results in unbounded memory allocation, exhausting the JVM heap and causing service unavailability. In order to exploit this vulnerability, the attack should have enough privileges in the targeted system to include the maliciously crafted policy document or trick the user to consume it.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (8)
- http://www.openwall.com/lists/oss-security/2026/05/01/6 Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2026-42402 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2464315 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-26485 Advisory
- https://github.com/advisories/GHSA-g36m-9g3m-2vmp Advisory
- https://lists.apache.org/thread/p826j0phhmr9f83wzpmys1y0bdfrr2q4 vendor-advisoryMailing ListVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-42402
- https://www.cve.org/CVERecord?id=CVE-2026-42402
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/05/01/6 | Mailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2026-42402 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2464315 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-26485 | Advisory | |
| https://github.com/advisories/GHSA-g36m-9g3m-2vmp | Advisory | |
| https://lists.apache.org/thread/p826j0phhmr9f83wzpmys1y0bdfrr2q4 | vendor-advisoryMailing ListVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-42402 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-42402 |
Change history (0)
No recorded changes yet.